Skip to content
Apache AirflowGHSA-c732-xvv8-g94c

Command Injection in Apache Airflow and Apache Airflow MySQL Provider

Critical9.8CVE-2023-22884 · Published Jan 21, 2023 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
apache-airflow
PyPI
< 2.5.12.5.1
Details and references

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-77
Also known as
BIT-airflow-2023-22884, CVE-2023-22884, PYSEC-2026-268, PYSEC-2026-279

More Apache Airflow advisories

All Apache Airflow
DateAdvisory
Feb 242023Improper Input Validation vulnerability in the Apache Airflow Sqoop Provider.
CVE-2023-25693Critical9.8fixed in 3.1.1
Mar 152023Sensitive Information in Error Messages in Apache Airflow
CVE-2023-25695Medium5.3fixed in 2.5.2rc1
Nov 222022OS Command Injection in Apache Airflow
CVE-2022-40954Medium5.5fixed in 2.3.0
Nov 222022OS Command Injection in Apache Airflow
CVE-2022-38649Critical9.8fixed in 2.3.0
Nov 222022OS Command Injection in Apache Airflow
CVE-2022-40189Critical9.8fixed in 2.3.0
Nov 152022Apache Airflow Contains Open Redirect
CVE-2022-45402Medium6.1fixed in 2.4.3

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.